Showing posts with label Seagate. Show all posts
Showing posts with label Seagate. Show all posts

Friday, 30 October 2015

Seagate Unveils 8TB Hard Drive For Video Surveillance


Seagate has unveiled the first in China to 8TB of hard drive designed specifically for video surveillance is made. A total of 64 security cameras simultaneously send their data to the disk, which can be used 24 hours a day, 7 days a week, according to Storage Review.

According to Tech Times would Seagate have indicated that the earlier hard disks that developed were not able to cope with the requirements for the writing of data by video surveillance systems. The hard drives were therefore at risk to overheat. The now revealed 8TB of hard drive uses less power and offers rotating sensors to counteract the effects of vibration when the disc is used in a system with multiple disks. The disc is in the United States costs $ 385. A price in the Netherlands is not yet known.

Thursday, 22 October 2015

Leaks In Hard Disk Drives Seagate And Western Digital Unveiled


Researchers have identified vulnerabilities in the hard drives of both Seagate and Western Digital unveiled which no updates are available. Eric Windisch found multiple vulnerabilities in the Central Seagate NAS solutions for networked storage.

It appears that firmware updates are vulnerable to a man-in-the-middle attack, as they are offered over HTTP and are not signed. This allows an attacker located between the user and the Internet is install malicious firmware. Furthermore, the device appears to leak via a phpinfo page information to any unauthorized user information.

Users can also adjust each other's files, there is a general root password used to world-readable, the web application allows unauthorized modification of IP address and host name possible and local users can increase their rights to the NAS. Windisch Seagate inquired twice but got no response. That's why he decided to publish his findings.

Western Digital

In the case of Western Digital were examined different models in the My Passport series that can encrypt themselves. The Western Digital My Passport external hard drive that offers hardware encryption on certain models. Problems with the leaking of information from memory, weak encryption keys and even backdoors on some drives make it possible for an attacker to decrypting user data without a password, the researchers said in their report (pdf).

Thus it appears the hard drives come with a default password. In case the user changes the password and do this once, the key of the default password remains on the hard drive behind. This makes it easy for an attacker to decrypt the hard drive. The problem can be remedied by the password reset a second time, but this is probably not familiar to users.Western Digital has been informed by the researchers, but no solution has yet released.

Wednesday, 11 March 2015

Seagate Mentions Hacking NAS Unlikely


Owners of a Seagate NAS do not have to worry that their system will be hacked through a leak that recently public was made ​​and for which no update available yet, so the hard drive manufacturer to know.Early this month, a researcher revealed a vulnerability allowing attackers Business Seagate NAS systems that can take over connected to the internet.

An Internet scan yielded 2500 potentially vulnerable NAS systems. The researcher had the problem reported in early October last year to Seagate, but the manufacturer did not come with an update. Ultimately, the researchers then decided to publish the details. Yet there is no reason to worry, says Seagate. An attack on vulnerable NAS systems by the manufacturer's own website labeled a "unlikely scenario."

However, the manufacturer will come early May with an update to correct the detected problems. In addition Seagate advises clients how they can prevent their NAS is exposed to possible attacks. It boils down to UPnP port forwarding must be disabled. In case there is manual port forwarding selected forwarding HTTP and HTTPS must be turned off to the NAS.

Monday, 2 March 2015

Criticism Leak Discovered In Seagate NAS Systems

Seagate

A researcher has a critical vulnerability in several NAS hard drive manufacturer Seagate discovered that an attacker can potentially thousands of these devices on the internet can take over, but despite months of communication about the problem, there is still no update for affected users are available.

The problem is in the Seagate Business NAS systems, according to the researcher Beyond Binary be used by both consumers and businesses. Through the systems, it is possible to store data and to share. To create users, set access rights, file management and other issues are the NAS systems provide a web management application.

The researcher discovered that this application is based on three outdated technologies, namely PHP version 5.2.13 (2010), CodeIgniter 2.1.0 (2011) and Lighttpd 4.1.28 (2010). The versions of PHP and CodeIgniter contain several vulnerabilities. In addition, also found problems in the application developed by Seagate. An attacker who adapts the session cookie can therefore eventually execute code as the user "root".

Meanwhile, there are a Metasploit module and a Python script developed to vulnerable systems can be attacked. The requirement is that the NAS can be accessed via the internet. A search via the search engine Shodan yielded more than 2,500 potentially vulnerable NAS systems. The problem has been confirmed on NAS systems with firmware 2014.00319 and 2013.60311, but the researcher suggests that basically all firmware versions are vulnerable.

In addition to the access data to attack the NAS systems within an organization can have far greater consequences. The NAS does not work with Active Directory or LDAP. Therefore they need the password for each user who needs access locally. These passwords are vulnerable through the MD5 hashing algorithm hashed. According to the researcher NAS systems at companies are undoubtedly contain passwords that are reused by domain users. An attacker who has access to the NAS can thus steal the MD5 hashes and crack, and discover the domain data.

Despite the severity of the problem, there is no update available, and the question is whether that will come. On 7 October 2014, the researcher reported the problem to Seagate. Then followed sorts messages where it appeared difficult for the investigation to catch the right person. Late January a Seagate employee could reproduce the problem using the supplied exploit. The researcher stated on January 17 that he wanted to publish the issue on 1 March.

However, this did not lead to an update since last Thursday Seagate said that there is no solution yet available. Users who want to protect themselves get therefore advised to make the NAS not accessible from the public Internet and placing the devices behind a firewall and only give several reliable IP addresses access.